Skip to Content
PurviewIRAP Control Evidence (tenant scan)

IRAP Control Evidence

TL;DR: This skill inspects your Microsoft 365 tenant read-only and produces structured, control-by-control evidence that supports an IRAP assessment against the Australian Government Information Security Manual.

What does control-by-control IRAP evidence for Microsoft 365 mean?

Control-by-control IRAP evidence for Microsoft 365 is a per-control record of how your tenant is configured, gathered so an endorsed IRAP assessor can independently assess it against the Australian Government Information Security Manual. The Australian Cyber Security Centre governs IRAP, and this skill reads Microsoft Entra Conditional Access settings without changing them.

Microsoft’s own IRAP assessments cover Microsoft as a cloud service provider. They do not assess your tenant configuration, so you remain responsible for engaging an assessor to evaluate your implementation as deployed.

When should you run this skill?

Run this skill when you need read-only evidence of Microsoft Entra Conditional Access and authentication strength settings ahead of an IRAP assessment. It suits teams seeking approval to operate in line with the ISM, because you remain responsible for engaging an assessor and for controls within your own organisation.

  • “We have an IRAP assessment booked and need evidence for our Microsoft Entra controls.”
  • “Prepare control-by-control evidence before our assessor arrives.”
  • “Show me whether our Conditional Access policies require phishing-resistant MFA.”
  • “Identify gaps between our tenant and the control set our assessor gave us.”

How this skill works, step by step

  1. Confirm the assessment scope and the control set your assessor is using, then list the in-scope controls to be evidenced.
  2. Read Microsoft Entra Conditional Access policies, including the grant controls each policy uses.
  3. Identify which policies use the Require authentication strength control and which built-in or custom authentication strength each one applies: Multifactor authentication strength, Passwordless MFA strength or Phishing-resistant MFA strength.
  4. Record the observed value, the ISM control identifier your assessor supplied, and the source of each evidence item.
  5. Compare each observed value against the expected configuration for the target classification level.
  6. Compile the findings into a control-by-control evidence table and mark any control that cannot be evidenced read-only for manual attestation.

Output format

The skill emits one row per in-scope control. The ISM control identifier comes from your assessor’s control set, not from this skill.

ISM controlMicrosoft 365 sourceObserved stateExpected (target level)Evidence status
Supplied by assessorMicrosoft Entra Conditional AccessPolicy grants access with MFAPer assessor’s control setMet, Partially met or Not met
Supplied by assessorMicrosoft Entra authentication strengthsMultifactor authentication strength appliedPhishing-resistant MFA strength requiredNot met

A short summary accompanies the table:

  • Total in-scope controls evidenced and the count Met, Partially met, and Not met.
  • The controls requiring remediation before authorisation.
  • The target classification level the evidence was assessed against.
  • A note on any control that could not be evidenced read-only and needs manual attestation.

Licensing and permissions

  • Conditional Access, and therefore authentication strengths, requires a Microsoft Entra ID P1 licence.
  • Grant the account running the skill read-only access to Conditional Access configuration only. Confirm the exact role and Microsoft Graph permission on Microsoft Learn before granting it.

Scope and safety

This skill is read-only by default and changes no tenant configuration.

This skill does NOT:

  • Modify, create, or delete any policy or setting.
  • Issue or grant an IRAP authorisation or replace an endorsed IRAP assessor, who provides the independent assessment.
  • Export or copy customer content or message bodies; it reads configuration metadata only.
  • Evaluate on-premises or non-Microsoft systems outside the Microsoft 365 tenant.

Sources

Reviewed 2026-09-30: removed ISM control identifiers, licence, role, Microsoft Graph permission, Essential Eight, risk-scoring and Purview, Defender and OFFICIAL: Sensitive references that no cited page supports; replaced a broken Microsoft Learn link; narrowed the scope to Microsoft Entra Conditional Access.


Licensed under CC BY 4.0  by EDUC4TE .

SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload
▸ View skill file
How to use this skill
  1. Get the file. Download or copy the SKILL.md from the SKILL.md panel on this page.
  2. Load it into your host:
    • Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
    • Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
    • Any chat host — paste the file contents as your prompt.
  3. Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
  4. Provide your tenant scope and run it (a site, a collection, or the whole tenant).
  5. Review the report and action the risk-ranked recommendations.

This skill is read-only by default — it inspects and reports, and never changes your tenant.

Get SKILL.md

Last reviewed 2026-09-30 · Published 2026-06-04

Last updated on